Analytics BIOC Informational

Abnormal User Login to Domain Controller

A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts (T1078) Use Alternate Authentication Material (T1550)
Attacker's goals:

A malicious user may attempt to access a domain controller to access and control Active Directory.

Investigative actions:

Ensure that the user is not a Domain Admin account. By default, Administrator groups have permission to access the domain controller. Check if the user is a service account that accesses a domain controller as part of its normal behavior. Verify that the user is not authenticating to group policy.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • Rare RDP User Login to Domain Controller by an Abnormal Department Medium (parent: Informational)
  • Abnormal RDP User Login to Domain Controller Low (parent: Informational)
  • RDP User Login to Domain Controller Informational
  • Abnormal User Login to Domain Controller by an Abnormal Department Informational